Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    PFSense no internet

    Scheduled Pinned Locked Moved General pfSense Questions
    13 Posts 4 Posters 1.1k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • M
      mikeehendricks
      last edited by

      Good Day,

      Hi. I am a newbie on using PFSense. Why i can't ping outside network on VLAN 10,11 and 50? I already assigned IP's on PFSense. But when i ping 1.1.1.1 from CS01, i can go through. I also done routing on CS01. The VLANs are also handled by CS01. I hope someone can help me resolve my issue. Please see images below for reference.
      f219de83-15bb-49c8-8c50-cde67e3be709-image.png
      0f6269a5-85f3-4f94-89ac-3ced67475780-image.png
      896250e7-3627-4a61-95d2-fc73b88573ca-image.png

      S 1 Reply Last reply Reply Quote 0
      • S
        SteveITS Galactic Empire @mikeehendricks
        last edited by

        @mikeehendricks Are those other subnets being NATted? try changing the rule from “LAN Subnets” to “any” or an alias that includes the other networks.

        Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
        When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
        Upvote 👍 helpful posts!

        M 1 Reply Last reply Reply Quote 0
        • M
          mikeehendricks @SteveITS
          last edited by

          @SteveITS I already change the source to "ANY", but still i can't ping outside from VLAN 11.

          68443f30-92c0-4bc8-91a0-4c027d4fa963-image.png

          S 1 Reply Last reply Reply Quote 0
          • stephenw10S
            stephenw10 Netgate Administrator
            last edited by

            Check the rules in Firewall > NAT > Outbound. Either whatever you've added manually or the auto rules. Are there rules for those VLAN subnets?

            M 1 Reply Last reply Reply Quote 0
            • S
              SteveITS Galactic Empire @mikeehendricks
              last edited by

              @mikeehendricks Traceroute from VLAN10 to 1.1.1.1 and see how far you get.

              Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
              When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
              Upvote 👍 helpful posts!

              M 1 Reply Last reply Reply Quote 0
              • M
                mikeehendricks @stephenw10
                last edited by

                @stephenw10 Here is my Outbout NAT config
                631a33c4-c8e1-4922-a996-6d2c4b482d95-image.png

                1 Reply Last reply Reply Quote 0
                • M
                  mikeehendricks @SteveITS
                  last edited by

                  @SteveITS As from vlan10/11, i could only get into 192.168.11.1, i could not get beyond that but when i ping 10.0.28.2 from VLAN 11, it go through.
                  b4f68f45-00dd-43f5-aa4a-9a33f2553138-image.png
                  0c4391cb-5412-41e5-9ea5-d0e19e4d3bf6-image.png

                  S 1 Reply Last reply Reply Quote 0
                  • S
                    SteveITS Galactic Empire @mikeehendricks
                    last edited by

                    @mikeehendricks said in PFSense no internet:

                    192.168.11.1

                    And that is CS01 correct, from your screen cap above? Is CS01 routing that subnet on to pfSense? Seems like it is not since there is no response from pfSense.

                    @mikeehendricks said in PFSense no internet:

                    when i ping 10.0.28.2 from VLAN 11, it go through

                    10.0.28.2 is the outside of CS01... So CS01 knows where that IP is, and can even answer because CS01 is 10.0.28.2.

                    Can you ping 10.0.28.1, the pfSense IP in 10.0.28.0/24? I would think not if CS01 isn't set up to route those subnets.

                    Pre-2.7.2/23.09: Only install packages for your version, or risk breaking it. Select your branch in System/Update/Update Settings.
                    When upgrading, allow 10-15 minutes to restart, or more depending on packages and device speed.
                    Upvote 👍 helpful posts!

                    M 2 Replies Last reply Reply Quote 0
                    • M
                      mikeehendricks @SteveITS
                      last edited by

                      @SteveITS 10.0.28.1 is accessible from CS01. Is there any config that i can do to be able to access 10.0.28.1 from inside VLAN 10/11?
                      7298bd58-e305-4960-a3db-d475a6cddb50-image.png

                      1 Reply Last reply Reply Quote 0
                      • M
                        mikeehendricks @SteveITS
                        last edited by mikeehendricks

                        @SteveITS When i check the States of LAN rules, i can see the IP that im pinging inside VLAN 11, but on the PC it's still request timed out
                        b4e5ea88-b701-4494-9c0e-3b6135ad849f-image.png
                        3bf6e130-74a7-4e59-a410-1dbddf09e26d-image.png
                        3b927baf-1564-4d4f-94cc-34e564cdcd16-image.png

                        M 1 Reply Last reply Reply Quote 0
                        • M
                          mcury Rebel Alliance @mikeehendricks
                          last edited by mcury

                          @mikeehendricks Seems to me that CS01 is sending the packet to pfsense, but pfsense doesn't have a route back since those networks are not directly connected to it, they are behind CS01, right ?

                          Try to add a static route in pfsense, pointing to those networks behind CS01 with the next hop being 10.0.28.2 (Gi0/0) of CS01. I'm assuming that is a layer 3 switch ? You would also need to create a NAT in pfsense allowing those networks.

                          dead on arrival, nowhere to be found.

                          M 1 Reply Last reply Reply Quote 0
                          • M
                            mikeehendricks @mcury
                            last edited by mikeehendricks

                            @mcury I already add a route from VLAN 10/11 to 10.0.28.2, and it works!
                            64084753-2942-476c-b789-980853e49a73-image.png
                            ca2b5915-dad3-4c27-ba9d-edb4eb562292-image.png
                            Thanks for your help!

                            M 1 Reply Last reply Reply Quote 1
                            • M
                              mcury Rebel Alliance @mikeehendricks
                              last edited by

                              @mikeehendricks said in PFSense no internet:

                              Thanks for your help!

                              You are welcome, glad that it helped.

                              dead on arrival, nowhere to be found.

                              1 Reply Last reply Reply Quote 1
                              • First post
                                Last post
                              Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.